Yang Zhang | CV Q [email protected] • Œ yangzhangalmo.github.com last update: September 28, 2021

Employment CISPA Helmholtz Center for Saarbrücken, Germany Faculty February 2020 – CISPA Helmholtz Center for Information Security Saarbrücken, Germany Research Group Leader January 2019 – January 2020 CISPA, Saarbrücken, Germany Postdoctoral Researcher January 2017 – December 2018 Host: Michael Backes

Education University of Luxembourg Luxembourg, Luxembourg Ph.D. in , highest honor December 2012 – November 2016 Supervisor: Sjouke Mauw and Jun Pang Shandong University Jinan, China Master in Computer Science September 2009 – June 2012 University of Luxembourg Luxembourg, Luxembourg Master in Informatics, exchange student September 2010 – October 2011 Shandong University Jinan, China Bachelor in Software Engineering September 2005 – June 2009 Research Projects Leading Scientist Helmholtz Medical Security, Privacy, and AI Research Center November 2018 - co-PI Helmholtz Pilot Funding “TFDA” (∼120,000 Euro) December 2019 - November 2022 Research Interests Privacy, , Social Network Analysis, Algorithmic Fairness, Urban Informatics

Service

+ PC member - 2022: USENIX Security, WWW, ICLR, AAAI, PETS, ASIACCS - 2021: USENIX Security, CCS, WWW, AAAI, Euro S&P, PETS, ASIACCS, ESORICS, SACMAT - 2020: CCS, WWW, ICWSM, RAID, PETS, ESORICS, Socinfo, SACMAT - 2019: CCS, Socinfo, ISMB/ECCB, SACMAT

1/7 Awards

+ Distinguished paper award, NDSS 2019 + Distinguished reviewer award, TrustML Workshop 2020 (co-located with ICLR 2020) + Best paper award, ARES 2014

Publication

Conference...... [1] Yugeng Liu and Rui Wen and Xinlei He and Ahmed Salem and Zhikun Zhang and Michael Backes and Emiliano De Cristofaro and Mario Fritz and Yang Zhang. ML-Doctor: Holistic Risk Assessment of Inference Attacks Against Machine Learning Models. In USENIX Security Symposium (USENIX Security). USENIX, 2022.

[2] Zhikun Zhang and Min Chen and Michael Backes and Yun Shen and Yang Zhang. Inference Attacks Against Graph Neural Networks. In USENIX Security Symposium (USENIX Security). USENIX, 2022.

[3] Xinlei He and Yang Zhang. Quantifying and Mitigating Privacy Risks of Contrastive Learning. In ACM SIGSAC Conference on Computer and Communications Security (CCS). ACM, 2021.

[4] Min Chen and Zhikun Zhang and Tianhao Wang and Michael Backes and Mathias Humbert and Yang Zhang. When Machine Unlearning Jeopardizes Privacy. In ACM SIGSAC Conference on Computer and Communications Security (CCS). ACM, 2021.

[5] Minxing Zhang and Zhaochun Ren and Zihan Wang and Pengjie Ren and Zhumin Chen and Pengfei Hu and Yang Zhang. Membership Inference Attacks Against Recommender Systems. In ACM SIGSAC Conference on Computer and Communications Security (CCS). ACM, 2021.

[6] Zheng Li and Yang Zhang. Membership Leakage in Label-Only Exposures. In ACM SIGSAC Conference on Computer and Communications Security (CCS). ACM, 2021.

[7] Xiaoyi Chen and Ahmed Salem and Michael Backes and Shiqing Ma and Qingni Shen and Zhonghai Wu and Yang Zhang. BadNL: Backdoor Attacks Against NLP Models. In Annual Computer Security Applications Conference (ACSAC). ACSAC, 2021.

[8] Xinlei He and Jinyuan Jia and Michael Backes and Neil Zhenqiang Gong and Yang Zhang. Stealing Links from Graph Neural Networks. In USENIX Security Symposium (USENIX Security), pages 2669–2686. USENIX, 2021.

[9] Zhikun Zhang and Tianhao Wang and Jean Honorio and Ninghui Li and Michael Backes and Shibo He and Jiming Chen and Yang Zhang. PrivSyn: Differentially Private Data Synthesis. In USENIX Security Symposium (USENIX Security), pages 929–946. USENIX, 2021.

[10] Fatemeh Tahmasbi and Leonard Schild and Chen Ling and Jeremy Blackburn and Gianluca Stringhini and Yang Zhang and Savvas Zannettou. “Go eat a bat, Chang!”: On the Emergence of Sinophobic Behavior on Web Communities in the Face of COVID-19. In The Web Conference (WWW). ACM, 2021.

2/7 [11] Rui Wen and Yu Yu and Xiang Xie and Yang Zhang. LEAF: A Faster Secure Search Algorithm via Localization, Extraction, and Reconstruction. In ACM SIGSAC Conference on Computer and Communications Security (CCS), pages 1219–1232. ACM, 2020.

[12] Dingfan Chen and Ning Yu and Yang Zhang and Mario Fritz. GAN-Leaks: A Taxonomy of Membership Inference Attacks against Generative Models. In ACM SIGSAC Conference on Computer and Communications Security (CCS), pages 343–362. ACM, 2020.

[13] Ahmed Salem and Apratim Bhattacharya and Michael Backes and Mario Fritz and Yang Zhang. Updates-Leak: Data Set Inference and Reconstruction Attacks in Online Learning. In USENIX Security Symposium (USENIX Security), pages 1291–1308. USENIX, 2020.

[14] Inken Hagestedt and Mathias Humbert and Pascal Berrang and Irina Lehmann and Roland Eils and Michael Backes and Yang Zhang. Membership Inference Against DNA Methylation Databases. In IEEE European Symposium on Security and Privacy (Euro S&P), pages 509–520. IEEE, 2020.

[15] Yang Zhang and Mathias Humbert and Bartlomiej Surma and Praveen Manoharan and Jilles Vreeken and Michael Backes. Towards Plausible Graph Anonymization. In Network and Distributed System Security Symposium (NDSS). Internet Society, 2020.

[16] Jinyuan Jia and Ahmed Salem and Michael Backes and Yang Zhang and Neil Zhenqiang Gong. MemGuard: Defending against Black-Box Membership Inference Attacks via Adversarial Examples. In ACM SIGSAC Conference on Computer and Communications Security (CCS), pages 259–274. ACM, 2019.

[17] Zheng Li and Chengyu Hu and Yang Zhang and Shanqing Guo. How to Prove Your Model Belongs to You: A Blind-Watermark based Framework to Protect Intellectual Property of DNN. In Annual Computer Security Applications Conference (ACSAC), pages 126–137. ACSAC, 2019.

[18] Zhiqiang Zhong and Yang Zhang and Jun Pang. A Graph-Based Approach to Explore Relationship Between Hashtags and Images. In International Conference Web Information Systems Engineering (WISE), pages 473–488. Springer, 2019.

[19] Tahleen Rahman and Bartlomiej Surma and Michael Backes and Yang Zhang. Fairwalk: Towards Fair Graph Embedding. In International Joint Conferences on Artifical Intelligence (IJCAI), pages 3289–3295. IJCAI, 2019.

[20] Yang Zhang. Language in Our Time: An Empirical Analysis of Hashtags. In The Web Conference (WWW), pages 2378–2389. ACM, 2019.

[21] Ahmed Salem and Yang Zhang and Mathias Humbert and Pascal Berrang and Mario Fritz and Michael Backes. ML-Leaks: Model and Data Independent Membership Inference Attacks and Defenses on Machine Learning Models. In Network and Distributed System Security Symposium (NDSS). Internet Society, 2019.

[22] Inken Hagestedt and Yang Zhang and Mathias Humbert and Pascal Berrang and Haixu Tang and XiaoFeng Wang and Michael Backes. MBeacon: Privacy-Preserving Beacons for DNA Methylation Data. In Network and Distributed System Security Symposium (NDSS). Internet Society, 2019.

3/7 [23] Fanghua Zhao and Linan Gao and Yang Zhang and Zeyu Wang and Bo Wang and Shanqing Guo. You Are Where You App: An Assessment on Location Privacy of Social Applications. In International Symposium on Software Reliability Engineering (ISSRE), pages 236–247. IEEE, 2018.

[24] Yang Zhang and Mathias Humbert and Tahleen Rahman and Cheng-Te Li and Jun Pang and Michael Backes. Tagvisor: A Privacy Advisor for Sharing Hashtags. In The Web Conference (WWW), pages 287–296. ACM, 2018.

[25] Pascal Berrang and Mathias Humbert and Yang Zhang and Irina Lehmann and Roland Eils and Michael Backes. Dissecting Privacy Risks in Biomedical Data. In IEEE European Symposium on Security and Privacy (Euro S&P), pages 62–76. IEEE, 2018.

[26] Michael Backes and Mathias Humbert and Jun Pang and Yang Zhang. walk2friends: Inferring Social Links from Mobility Profiles. In ACM SIGSAC Conference on Computer and Communications Security (CCS), pages 1943–1957. ACM, 2017.

[27] Jun Pang and Yang Zhang. Quantifying Location Sociality. In ACM Conference on Hypertext and Social Media (HT), pages 145–154. ACM, 2017.

[28] Jun Pang and Yang Zhang. DeepCity: A Feature Learning Framework for Mining Location Check-Ins. In International Conference on Weblogs and Social Media (ICWSM), pages 652–655. AAAI, 2017.

[29] Yan Wang and Zongxu Qin and Jun Pang and Yang Zhang and Xin Jin. Semantic Annotation for Places in LBSN Using Graph Embedding. In ACM International Conference on Information and Knowledge Management (CIKM), page 2343–2346. ACM, 2017.

[30] Yang Zhang and Minyue Ni and Weili Han and Jun Pang. Does #like4like Indeed Provoke More Likes? In International Conference on Web Intelligence (WI), pages 179–186. ACM, 2017.

[31] Minyue Ni and Yang Zhang and Weili Han and Jun Pang. An Empirical Study on User Access Control in Online Social Networks. In ACM Symposium on Access Control Models and Technologies (SACMAT), pages 12–23. ACM, 2016.

[32] Jun Pang and Polina Zablotskaia and Yang Zhang. On Impact of Weather on Human Mobility in Cities. In International Conference Web Information Systems Engineering (WISE), pages 247–256. Springer, 2016.

[33] Jun Pang and Yang Zhang. Location Prediction: Communities Speak Louder than Friends. In ACM Conference on Online Social Networks (COSN), pages 161–171. ACM, 2015.

[34] Yang Zhang and Jun Pang. Distance and Friendship: A Distance-based Model for Link Prediction in Social Networks. In Asia-Pacific Web Conference (APWeb), pages 55–66. Springer, 2015.

[35] Jun Pang and Yang Zhang. Event Prediction with Community Leaders. In Conference on Availability, Reliability and Security (ARES), pages 238–243. IEEE, 2015.

[36] Marcos Cramer and Jun Pang and Yang Zhang. A Logical Approach to Restricting Access in Online Social Networks. In ACM Symposium on Access Control Models and Technologies (SACMAT), pages 75–86. ACM, 2015.

4/7 [37] Jun Pang and Yang Zhang. Cryptographic Protocols for Enforcing Relationship-based Access Control Policies. In Annual IEEE Computers, Software and Applications Conference (COMPSAC), pages 484–493. IEEE, 2015.

[38] Jun Pang and Yang Zhang. Exploring Communities for Effective Location Prediction. In International Conference on World Wide Web (WWW), pages 87–88. ACM, 2015.

[39] Yang Zhang and Jun Pang. Community-driven Social Influence Analysis and Applications. In International Conference on Web Engineering (ICWE). Springer, 2015.

[40] Jun Pang and Yang Zhang. A New Access Control Scheme for Facebook-style Social Networks. In Conference on Availability, Reliability and Security (ARES), pages 1–10. IEEE, 2014.

Journal...... [41] Xinlei He and Qingyuan Gong and Yang Chen and Yang Zhang and Xin Wang and Xiaoming Fu. DatingSec: Detecting Malicious Accounts in Dating Apps Using a Content-Based Attention Network. IEEE Transactions on Dependable and Secure Computing, 2021.

[42] Bo-Heng Chen and Cheng-Te Li and Kun-Ta Chuang and Jun Pang and Yang Zhang. An Active Learning-based Approach for Location-aware Acquaintance Inference. Knowledge and Information Systems, 2018.

[43] Jun Pang and Yang Zhang. A New Access Control Scheme for Facebook-style Social Networks. Computers & Security, 2015.

Teaching

Lectures...... Instructor Seminar: Privacy of Machine Learning October 2021 - February 2021, Saarland University Instructor Advanced Lecture: Privacy Enhancing Technologies May 2021 - September 2021, Saarland University Instructor Seminar: Data-driven Understanding of the Disinformation Epidemic May 2021 - September 2021, Saarland University Instructor Seminar: Data Privacy October 2020 - February 2021, Saarland University Instructor Advanced Lecture: Privacy Enhancing Technologies May 2020 - September 2020, Saarland University Instructor Seminar: Data-driven Approaches on Understanding Disinformation May 2020 - September 2020, Saarland University Instructor Seminar: Data Privacy October 2019 - February 2020, Saarland University Instructor Advanced Lecture: Privacy Enhancing Technologies April 2019 - September 2019, Saarland University Instructor Seminar: Biomedical Privacy April 2019 - September 2019, Saarland University

5/7 Instructor Seminar: Data Privacy October 2018 - February 2019, Saarland University Instructor Advanced Lecture: Privacy Enhancing Technologies April 2018 - September 2018, Saarland University Instructor Seminar: Adversarial Machine Learning April 2018 - September 2018, Saarland University

Summer School...... Instructor AI Security Summer School August 2020, Zhejiang University Instructor InForSec Summer School July 2020, Tsinghua University Instructor G.O.S.S.I.P. Summer School August 2019, Shanghai Jiao Tong University Instructor InForSec Summer School July 2019, Tsinghua University Students

Ph.D. Students...... Xinlei He CISPA Helmholtz Center for Information Security February 2020 - Zheng Li CISPA Helmholtz Center for Information Security February 2021 -

Co-supervised Ph.D. Students...... Min Chen CISPA Helmholtz Center for Information Security with Michael Backes August 2019 - Yihan Ma CISPA Helmholtz Center for Information Security with Michael Backes July 2021 - Ahmed Salem CISPA Helmholtz Center for Information Security with Michael Backes February 2017 - Bartlomiej Surma CISPA Helmholtz Center for Information Security with Michael Backes June 2016 - Yang Zou CISPA Helmholtz Center for Information Security with Michael Backes August 2019 -

Ph.D. Preparatory Phase...... Yiyong Liu CISPA Helmholtz Center for Information Security October 2021 - Yugeng Liu CISPA Helmholtz Center for Information Security October 2019 - Xinyue Shen CISPA Helmholtz Center for Information Security May 2021 -

6/7 Rui Wen CISPA Helmholtz Center for Information Security October 2019 - Minxing Zhang CISPA Helmholtz Center for Information Security May 2021 -

Visitors...... Haiming Wang Zhejiang University visiting Ph.D. student July 2021 -

Alumni...... Joann Chen UC Irvine intern July 2021 - September 2021 Ge Han Shandong University visiting Ph.D. student October 2019 - August 2021 Suliya Chinese Academy of Science visiting Ph.D. student January 2020 -January 2021 Xiaoyi Chen Peking University visiting Ph.D. student October 2019 - October 2020 Yuhao Mao Zhejiang University intern June 2020 - September 2020 Leonard Schild Saarland University research assistant March 2017 - July 2020 Tianhao Wang Purdue University intern February 2020 - March 2020 Zeyu Yang Zhejiang University visiting Ph.D. student October 2019 - March 2020

Bachelor/Master Thesis Students...... Ran Cheng University of Luxembourg March 2015 - September 2015 Haftom Meles Saarland University January 2019 - June 2019 Arthur Sanin Saarland University August 2019 - December 2019 Yannick Sautter Saarland University December 2019 - May 2020 Franz Schramm Saarland University August 2019 - December 2019

7/7